
GIAC Cloud Threat Detection
Domain 4Objective 2
Investigating Azure Environments GCTD Practice Questions (Page 3)
Part of the Cloud Provider Investigations domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
14concepts
Questions 11–15
- 11
Which AKS resource provides a chronological record of events in the cluster, such as pod creation failures or image pull errors?
Select an answer first - 12
Which of the following is a potential indicator of secret misuse in Key Vault logs?
Select an answer first - 13
An investigator wants to quickly list all virtual machines in a specific resource group using the Azure CLI. Which command retrieves a list of VMs in a resource group?
Select an answer first - 14
An organization suspects that a storage account containing sensitive documents was accessed by an unauthorized party. You need to determine whether any data was read or downloaded from the storage account. Which log source should you analyze first?
Select an answer first - 15
An analyst is investigating suspicious activity within a virtual machine, such as unusual processes or file access. Which type of Azure log would contain this data-plane information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.